FBI ejects Accenture contractor after patch failure leads to data breach
The FBI removed an Accenture subcontractor after a missed security patch exposed personal data of thousands of its employees.
According to FBI cyber chief Brett Leatherman, a contractor from a third-party firm did not install a security patch that had been issued for a platform the agency manages, resulting in a breach that exposed personal details of thousands of FBI staff. Sources identified the platform as Oracle's PeopleSoft, a human-resources application that was earlier exploited by the hacking group ShinyHunters to infiltrate the bureau's job site.
Following the incident, the FBI terminated the contractor's access and implemented measures to mitigate further risk. The unnamed contractor was linked to Accenture, which issued a statement expressing pride in supporting the FBI's mission while declining to address the patch failure. Oracle has not provided comment on the matter.
How this was covered
- Left-leaning outlets covered this 4h later
Why it matters
A missed security patch compromised sensitive FBI employee data, highlighting risks of third-party IT management.
In this story
Related stories
2 in this thread